Mobile Device Data Sanitization via Grace Window Disconnection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies for protecting data on mobile devices in network environments are inadequate, as they may not ensure complete sanitization, especially when devices are disconnected from the network or in the possession of unauthorized users, leading to potential data leakage and misappropriation.

Innovation Solution

A communication system that enables mobile devices to automatically sanitize themselves by deleting selected or all objects after a predetermined 'grace window' of disconnection from the central network, regardless of the central security system's online status, using a local sanitization module and configuration settings that include a grace window for disconnection and data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile devices are integrated into protected network environments with network access rights, then data accessibility and user mobility are improved, but data security and protection against misappropriation deteriorate

Engineering Contradiction:
Improvemobile device integrationVSAvoiddata misappropriation risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary sanitization actions by automatically deleting data from mobile devices before potential misappropriation can occur. The sanitization module continuously monitors and proactively removes sensitive information when devices disconnect from the network or when unauthorized access is detected, preventing data leakage before it can harm the organization.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile device performs self-sanitization through the integrated sanitization module that automatically detects disconnection events and executes data deletion without requiring external intervention. The device monitors its own network status and autonomously removes sensitive data, eliminating the need for continuous central system control while maintaining security.

Inventive Principle:
Principle #25Self-service

2Reliability

If automatic sanitization is implemented to prevent data leakage, then data protection is improved, but device complexity and operational overhead increase

Engineering Contradiction:
Improvedata protectionVSAvoidsanitization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The sanitization functionality is extracted as a separate, dedicated module within the mobile device that operates independently from the main operating system and network infrastructure. This modular approach contains complexity within a dedicated component while keeping the rest of the system simple, allowing the sanitization function to be added without fundamentally redesigning the entire device architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements feedback mechanisms where the sanitization module continuously monitors network connection status and device state, automatically triggering sanitization actions when conditions change. This closed-loop feedback system maintains data protection with minimal complexity by relying on simple status detection and automated responses rather than complex decision-making algorithms.

Inventive Principle:
Principle #23Feedback

3Reliability

If data is deleted from mobile devices to ensure sanitization, then data security is improved, but data availability and user productivity deteriorate

Engineering Contradiction:
Improvedata securityVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The sanitization system dynamically adjusts its behavior based on real-time conditions, allowing data access during network-connected states while automatically deleting data when disconnection or unauthorized access is detected. This dynamic approach ensures data is available when needed for productivity while maintaining security when access should be restricted, balancing both requirements through conditional automation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9351163B2Automatic sanitization of data on a mobile device in a network environment
Publication Date: 2016.05.24 MCAFEE LLC
  • US9351163B2 patent drawing
  • US9351163B2 patent drawing
  • US9351163B2 patent drawing

AI summary

A method is provided in one example embodiment and includes establishing a network connection to a central security system in a central network, receiving a message from the central security system, activating a grace window based on the message, and determining whether the grace window has expired. The method further includes deleting, when the grace window expires, one or more objects from the mobile device based on a sanitization policy. In specific embodiments, the network connection is terminated before the grace window expires, and the grace window expires unless the mobile device establishes another network connection with the central security system. In further embodiments, the method includes receiving the sanitization policy from the central security system. The sanitization policy identifies the one or more objects to be deleted from the mobile device when the grace window expires.